Important: kernel security update. Date: Mon, 3 Dec 2007 12:04:56 -0600 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for kernel on SL5.x i386/x86_64 Comments: To: "
Multiple vulnerabilities have been discovered in MadWifi, possibly allowing for the execution of arbitrary code or a Denial of Service.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200706-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: MadWifi: Multiple vulnerabilities Date: June 11, 2007 Bugs: #179532 ID: 200706-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been discovered in MadWifi, possibly allowing for the execution of arbitrary code or a Denial of Service. Background ========= The MadWifi driver provides support for Atheros based IEEE 802.11 Wireless Lan cards. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-wireless/madwifi-ng < 0.9.3.1 > = 0.9.3.1 Description ========== Md Sohail Ahmad from AirTight Networks has discovered a divison by zero in the ath_beacon_config() function (CVE-2007-2830). The vendor has corrected an input validation error in the ieee80211_ioctl_getwmmparams() and ieee80211_ioctl_getwmmparams() functions(CVE-207-2831), and an input sanitization error when parsing nested 802.3 Ethernet frame lengths (CVE-2007-2829). Impact ===== An attacker could send specially crafted packets to a vulnerable host to exploit one of these vulnerabilities, possibly resulting in the execution of arbitrary code with root privileges, or a Denial of Service. Workaround ========= There is no known workaround at this time. Resolution ========= All MadWifi users should upgrade to the latestversion: # emerge --sync # emerge --ask --oneshot --verbose "> =net-wireless/madwifi-ng-0.9.3.1" References ========= [ 1 ] CVE-2007-2829 https://www.cve.org/CVERecord?id=CVE-2007-2829 [ 2 ] CVE-2007-2830 https://www.cve.org/CVERecord?id=CVE-2007-2830 [ 3 ] CVE-2007-2831 https://www.cve.org/CVERecord?id=CVE-2007-2831 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200706-04 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
Updated package.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2006-256 2006-03-30 ---------------------------------------------------------------------Product : Fedora Core 5 Name : wpa_supplicant Version : 0.4.8 Release : 6.fc5 Summary : WPA/WPA2/IEEE 802.1X Supplicant Description : wpa_supplicant is a WPA Supplicant for Linux, BSD and Windows with support for WPA and WPA2 (IEEE 802.11i / RSN). Supplicant is the IEEE 802.1X/WPA component that is used in the client stations. It implements key negotiation with a WPA Authenticator and it controls the roaming and IEEE 802.11 authentication/association of the wlan driver. ---------------------------------------------------------------------Update Information: This update to wpa_supplicant provides: - Fixes for Orinoco-based wireless cards - Addition of the Prism54 (fullmac) WPA driver - Removal of the deprecated 'ipw' WPA driver, Intel Pro/Wireless users should use the 'wext' driver instead ---------------------------------------------------------------------* Mon Mar 27 2006 Dan Williams - 0.4.8-6 - Add patch to make orinoco happy with WEP keys - Enable Prism54-specific driver - Disable ipw-specific driver; ipw2x00 should be using WEXT instead ---------------------------------------------------------------------This update can be downloaded from: 80d6f1325f5df935dab6ee7d7da773fbe8998c27 SRPMS/wpa_supplicant-0.4.8-6.fc5.src.rpm a490f96ef48adaa1b8567c0ba9292bc6d16aca1b ppc/wpa_supplicant-0.4.8-6.fc5.ppc.rpm f0df53ce4ac2da2d576909c562541cb449600c7e ppc/wpa_supplicant-gui-0.4.8-6.fc5.ppc.rpm e7428397df6d9341e843d9cc18dd4b3c684e18e7 ppc/debug/wpa_supplicant-debuginfo-0.4.8-6.fc5.ppc.rpm 16d1d1c95effe972df8d56a358fd364ba1e40528 x86_64/wpa_supplicant-0.4.8-6.fc5.x86_64.rpm aa3386fac43cf5846e54471ba46d9935aa8e2f14 x86_64/wpa_supplicant-gui-0.4.8-6.fc5.x86_64.rpm 5ff81ac301dde8da90fd491073b59b009f031c79 x86_64/debug/wpa_supplicant-debuginfo-0.4.8-6.fc5.x86_64.rpm 0cf38f1ee3d9e8d07103a851467dd5fb95e2d381 i386/wpa_supplicant-0.4.8-6.fc5.i386.rpm 6586ae4af583756b42f833d892f2d9acde121d63 i386/wpa_supplicant-gui-0.4.8-6.fc5.i386.rpm a2b4b4210b63bd5ae2b32a2a26c7ffb70b7e25d6 i386/debug/wpa_supplicant-debuginfo-0.4.8-6.fc5.i386.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at . ----------------------------------------------------------------------- fedora-announce-list mailing list
Get the latest Linux and open source security news straight to your inbox.